CVE-2026-72266

Source
https://cve.org/CVERecord?id=CVE-2026-72266
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72266.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72266
Downstream
Published
2026-08-15T05:54:52.121Z
Modified
2026-08-16T03:48:39.256173038Z
Summary
fbdev: vesafb: fix memory leak in vesafb_probe()
Details

In the Linux kernel, the following vulnerability has been resolved:

fbdev: vesafb: fix memory leak in vesafb_probe()

Since commit 73ce73c30ba9 ("fbdev: Transfer video= option strings to caller; clarify ownership") the string returned from fbgetoptions() is expected to be freed by the caller. But the string is not freed in vesafb_probe(). Fix that by freeing the option string after setup.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72266.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
73ce73c30ba9ae4d90fdfad7ebe9104001d5d851
Fixed
124df55c7201d011a3fead2205685b6c47eae093
Fixed
43af398217ca8940bf30643fd1150b4c655b8a88
Fixed
58bc18e03481b62f0ec53fe47f36615d52660a7d
Fixed
7b96ce9f8e47538c3c6eebbb217c94d696975cac
Fixed
b15d708995c01bbffe7dcd634a31959f6805bed3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72266.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72266.json"